PSIRT Advisory

XSS vulnerability in the FortiManager via the buffer parameter

Summary

An improper neutralization of input vulnerability in FortiManager GUI may allow an authenticated attacker to perform an XSS (Cross Site Scripting) attack via the buffer parameter.

Impact

Execute unauthorized code or commands

Affected Products

FortiManager 6.2.1 and below

Solutions

Upgrade to FortiManager 6.2.2 or above

Acknowledgement

Fortinet is pleased to thank Patrick Nielsen for reporting this vulnerability under responsible disclosure.